Getting "probed" by NTL customers.....
10-06-2004, 22:36
|
#1
|
|
Guest
|
Getting "probed" by NTL customers.....
OK, what is going on? My FTP server which is running black ice defender is reporting people on NTL port scanning me, such as HTTP scans and FTP scans. Some one tried it 36 times, and I'm wanting to know if this is on purpose or they have caught a program that does this.
Any ideas?
|
|
|
|
10-06-2004, 22:53
|
#2
|
|
Inactive
Join Date: Jun 2003
Location: Various
Services: 9am, 1pm and 8pm daily
Posts: 2,055
|
Re: Getting "probed" by NTL customers.....
Port scans are against ntl's Residential Internet Terms & Conditions. Please report such activity to the Abuse team by visiting www.ntlworld.com/netreport
Thanks!
|
|
|
10-06-2004, 22:54
|
#3
|
|
cf.mega poster
Join Date: Nov 2003
Location: Reading
Age: 41
Services: Virgin Media Broadband Size M
Posts: 6,546
|
Re: Getting "probed" by NTL customers.....
It could be either... either way report it to the abuse team ( www.ntlworld.com/netreport)
the policy on port scanning is three strikes and your out.
EDIT: Jimbo beat me to it...
|
|
|
10-06-2004, 23:05
|
#4
|
|
Guest
|
Re: Getting "probed" by NTL customers.....
It asks for evidence, but I can't find a program to open up Black Ice's evidence file. Any ideas of one on the net to show the proof of them both?
|
|
|
|
10-06-2004, 23:06
|
#5
|
|
cf.mega poster
Join Date: Nov 2003
Location: Reading
Age: 41
Services: Virgin Media Broadband Size M
Posts: 6,546
|
Re: Getting "probed" by NTL customers.....
what form is the output from black ice? there should be a text log file and you can just copy and paste the appropriate part
|
|
|
10-06-2004, 23:08
|
#6
|
|
Guest
|
Re: Getting "probed" by NTL customers.....
Black Ice uses .enc because it saves a packet and gives detailed information about it. I think I have found a decoder though
EDIT: This is going to be hard, it's a load of code I don't understand
|
|
|
|
10-06-2004, 23:22
|
#7
|
|
Inactive
Join Date: Oct 2003
Location: 2nd CPU to the right & past the cache
Posts: 1,949
|
Re: Getting "probed" by NTL customers.....
Extract from http://www.iss.net/security_center/a...14/default.htm
The Packet Log and Evidence Log features of BlackICE generate files with the extension ".enc". These ".enc" files contain actual network traffic and in the case of evidence files, they contain traffic that was part of the detected attacks. These files are not readable by normal text editor programs, such as Notepad, but must instead be decoded by standard protocol analyzer programs (sniffers) that network technicians typically use to analyze network traffic.
You can find sniffers (protocol analyzers) to read the packet log and evidence log files at the following web sites: That said, you can read some of the log in texteditors like notepad, but not much of it will make sense, unless some plain text was included in the packet that triggered the capture
|
|
|
10-06-2004, 23:44
|
#8
|
|
Guest
|
Re: Getting "probed" by NTL customers.....
What part on Ethereal am I supposed to copy and past? I found the IP of the attacker and the port he scanned me (80), but in the middle window I don't know what lines I need to tell NTL about.
|
|
|
|
11-06-2004, 00:33
|
#9
|
|
Dr Pepper Addict
Cable Forum Admin
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,705
|
Re: Getting "probed" by NTL customers.....
All NTL really need are the IP, the port scanned and the time/frequency of the scans. Unless it is persistant then it is probably not worth bothering.
__________________
Baby, I was born this way.
|
|
|
11-06-2004, 00:51
|
#10
|
|
cf.mega poster
Join Date: Nov 2003
Location: Reading
Age: 41
Services: Virgin Media Broadband Size M
Posts: 6,546
|
Re: Getting "probed" by NTL customers.....
Quote:
|
Originally Posted by Electrolyte
What part on Ethereal am I supposed to copy and past? I found the IP of the attacker and the port he scanned me (80), but in the middle window I don't know what lines I need to tell NTL about.
|
might as well copy all information that you think might be relevant... someone working for the abuse team can sort through it
At the time of the Blaster/ Welchia worms i was sending 150+ pages of router logs everyday to one of the teams at work so they could get all of the ips. Needless to say they did a pretty good job of sorting through them
|
|
|
11-06-2004, 08:52
|
#13
|
|
In the corner, sulking.
Join Date: Jun 2003
Location: Shaw, Oldham, Lancashire.
Services: 2 TV 360 boxes. 500mb BB, Phone line.
Posts: 8,041
|
Re: Getting "probed" by NTL customers.....
I use this. http://www.visualizesoftware.com/for Zone Alarm, they do a version for Black Ice, not free but produces loads of extra info on your firewall activity and can generate email messages from within the program that you can send to abuse@ anywhere.
|
|
|
11-06-2004, 09:10
|
#14
|
|
Guest
|
Re: Getting "probed" by NTL customers.....
I installed mynetwatchman, and it sent off all the "possible" attacks I had in my Black Ice attack list. At least it's automatic
|
|
|
|
11-06-2004, 09:57
|
#15
|
|
Inactive
Join Date: Jun 2003
Location: Stafford
Age: 52
Services: Sky World
300k BB
NTL Phone
Posts: 2,399
|
Re: Getting "probed" by NTL customers.....
Are you positive they are "attacks" it could just be normal internet traffic?
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 08:54.
|